When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,374 vulnerabilities with CWE-287
CVE-2012-6437
CRITICAL
Rockwellautomation Controllogix Controllers - Authentication Bypass
CVSS 9.8
CVE-2012-4545
ELinks < 0.12pre6 - Credential Delegation via HTTP Negotiate Authentication
CVE-2012-4688
i-GEN opLYNX < 2.01.9 - Unauthenticated Authentication Bypass via JavaScript Disabling
CVE-2012-5930
NetIQ Privileged User Manager < 2.3.1 HF2 - Unauthenticated Password Change via AMF Request
CVE-2012-3002
Foscam/Wansview IP Cameras - Auth Bypass
CVE-2012-6067
freeFTPd <= 1.0.11 - Authentication Bypass via Crafted SFTP Session
CVE-2012-6066
freeSSHd < 1.2.6 - Unauthenticated Authentication Bypass via Crafted Session
CVE-2012-5975
SSH Tectia Server 6.0.4-6.3.2 - Authentication Bypass via Blank Password
CVE-2012-5858
Samsung Kies Air 2.1.207051 and 2.1.210161 - Improper Authentication via IP Address Spoofing
CVE-2012-4614
EMC Smarts NCM <9.1 - Info Disclosure
CVE-2012-2437
ar web content manager 2.2 - Unauthenticated Improper Authentication via cookie_gen.php
CVE-2012-2377
JBoss Enterprise Portal Platform < 5.2.1 and SOA Platform < 5.2.0 - Information Disclosure via JGroups
CVE-2012-5864
Sinapsi eSolar, eSolar DUO, eSolar Light, and sinapsi_firmware < 2.0.2870 - Unauthenticated Administrative Access
CVE-2012-5758
IBM WebSphere DataPower XC10 Appliance 2.0.0.0-2.0.0.3 and 2.1.0.0-2.1.0.2 - Unauthenticated Denial of Service
CVE-2012-5887
Apache Tomcat 5.5.0-5.5.35 - Improper Authentication via Stale Nonce Bypass
CVE-2012-5886
Apache Tomcat 5.5.x < 5.5.36, 6.x < 6.0.36, 7.x < 7.0.30 - Authentication Bypass via Session ID
CVE-2012-4613
EMC RSA Data Protection Manager <3.2.1 - Auth Bypass
CVE-2012-4021
MosP kintai kanri < 4.0.9 - Authenticated User Impersonation
CVE-2012-3315
IBM Tivoli Federated Identity Manager < 6.2.2 and Business Gateway < 6.2.1 - Sensitive Information Exposure
CVE-2012-4659
Cisco Adaptive Security Appliance Software 8.2-8.3 - Denial of Service via Crafted Authentication Response
CVE-2012-5353
Eduserv OpenAthens SP 2.0 - Auth Bypass
CVE-2012-5352
Java Open Single Sign-On Project Home - Authentication Bypass via SAML Assertion Signature Exclusion
CVE-2012-5351
Apache Axis2 < 1.6.4 - Authentication Bypass via SAML Signature Exclusion
CVE-2012-4418
Apache Axis2 < 1.7.9 - Authentication Bypass via XML Signature Wrapping Attack
CVE-2012-4457
OpenStack Keystone Essex < 2012.1.2 and Folsom < folsom-3 - Authenticated Improper Authentication
Details
Vulnerabilities
4,374
Exploit Likelihood
High